CVE detail
CVE-2025-6170
A flaw was found in the interactive shell of the xmllint command-line tool, used for parsing XML files. When a user inputs an overly long command, the program does not check the input size properly, which can cause it to crash. This issue might allow attackers to run harmful code in rare configurations without modern protections.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 25.6 · diversity 19.5 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 1
- within the 30d window
- Peak daily
- 1
- highest bucket
Evidence
Source links by recency
12 source links · newest first
- Siemens SINEC OSCISA Alerts
Metrics CVSS Version Base Score Base Severity Vector String 3.1 5.5 MEDIUM CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H CVE-2025-40214 In the Linux kernel, the following vulnerability has been resolved: af_unix: Initialise scc_index in unix_add_edge(). Quang Le reported that the AF_UNIX GC could garbage-collect a receive queue of an alive in-flight soc
governmentwww.cisa.govJul 7, 2026, 12:00 PM - https://access.redhat.com/errata/RHSA-2026:46836access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2026:44481access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2025, 4:15 PM - https://cert-portal.siemens.com/productcert/html/ssa-253495.htmlcert-portal.siemens.com
No excerpt available.
Vendor Advisorycert-portal.siemens.comJun 16, 2025, 4:15 PM No excerpt available.
Vendor Advisorylists.debian.orgJun 16, 2025, 4:15 PM- https://gitlab.gnome.org/GNOME/libxml2/-/issues/941gitlab.gnome.org
No excerpt available.
Exploitgitlab.gnome.orgJun 16, 2025, 4:15 PM - https://bugzilla.redhat.com/show_bug.cgi?id=2372952bugzilla.redhat.com
No excerpt available.
Exploitbugzilla.redhat.comJun 16, 2025, 4:15 PM - https://access.redhat.com/security/cve/CVE-2025-6170access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2026:7519access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2026:39317access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2026:39304access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2025, 4:15 PM - https://access.redhat.com/errata/RHSA-2026:36734access.redhat.com
No excerpt available.
Vendor Advisoryaccess.redhat.comJun 16, 2025, 4:15 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-6732CVSS 6.5 · Medium
A flaw was found in libxml2. This vulnerability occurs when the library processes a specially crafted XML Schema Definition (XSD) validated document that includes an internal enti…
- CVE-2026-0992CVSS 2.9 · Low
A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements poin…
- CVE-2026-0990CVSS 5.9 · Medium
A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delega…
- CVE-2026-0989CVSS 3.7 · Low
A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving…
- CVE-2025-6021CVSS 7.5 · High
A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memor…
- CVE-2026-9150CVSS 6.5 · Medium
A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata…